First published: Wed Feb 28 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postMash – custom post order.This issue affects postMash – custom post order: from n/a through 1.2.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
postMash | <=1.2.0 | |
WordPress MD Custom Content After or Before of Post | <=1.2.0 | |
WordPress | <=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25927 is classified as a critical severity SQL Injection vulnerability.
To fix CVE-2024-25927, update the postMash – custom post order plugin to version 1.2.1 or later.
CVE-2024-25927 affects the postMash – custom post order plugin versions up to and including 1.2.0.
CVE-2024-25927 is an SQL Injection vulnerability caused by improper neutralization of special elements in SQL commands.
The vendor for CVE-2024-25927 is Joel Starnes, associated with the postMash – custom post order plugin.